Quantcast
Channel: Questions in topic: "heavy-forwarder"
Viewing all articles
Browse latest Browse all 727

Why did Splunk restart heavy forwarder?

$
0
0
Got an alert for a HF restarting and trying to find the root cause of unexpected restart. I'm using the search below and the results shown are at the start of the event which led to the "Starting Splunk server daemon (splunkd)... " alert index=_internal source="/opt/splunk/var/log/splunk/splunkd_st*" host=MYHF Results: 4/22/20 1:14:38.000 PM Checking prerequisites... 4/22/20 1:14:38.000 PM Splunk> The IT Search Engine. 4/22/20 1:14:38.000 PM splunkd is not running. [FAILED] 4/22/20 1:14:34.824 PM 2020-04-22 13:14:34.824 -0400 splunkd started (build 6db836e2fb9e) pid=25388 4/22/20 1:14:34.000 PM Bypassing local license checks since this instance is configured with a remote license master. Is there anywhere I could look that could give a more specific reason as to why the HF restarted? Thanks in advance

Viewing all articles
Browse latest Browse all 727

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>